Excited to get started on 3 intense days of undistracted work on @owasp strategy! We have a packed agenda, covering projects, by-laws and policies, funding and grants, committees, and more! I look forward to sharing all these outputs!
2
4
1
17
Thank you for all you do!!! My recommendations - optimize the platform for contributors, go out and recruit new innovative projects to join OWASP, do some real fundraising, stop redoing the website, and stop trying to be a training/conferences company.
1
4
Thanks as always for the insightful input, Jeff! A lot of this I definitely agree with, and other excellent discussion points as well. Of course projects are a huge part of OWASP - but also not the only part, e.g. chapters, education, guidance, etc. Lots to talk about!
1
2
Chapters are great. Education and guidance are projects….unless you mean paid training (which I’m suggesting doesn’t match well with OWASP values or mission). I want an OWASP that is squarely focused on ideas that have a chance to change the trajectory of app/API security.
1
Thanks Jeff. Your two suggestions, boost fundraising and recruit new projects, fall into two committees, Funding (new) and Projects. Maybe you can bring your ideas and join one or both of those committees?
1
My suggestions can’t be implemented by committees. These are board level strategic decisions about the way OWASP works.
1
3
Are these strategic decisions a motion we pass? Or something else?

Sep 15, 2023 · 4:02 AM UTC

1
1
If I was on the board, I’d want a 3 year strategic plan detailing how OWASP achieves the mission and thrives. It’s not about the formalities. The board should be thinking, writing, asking, arguing, synthesizing, analyzing, creating….and ultimately agreeing and committing.
1
1
We just finished our strategic meetings where we did just that. Not a 3-year plan, but rather a reorganization around our core services. Write-ups are coming in the near future about the outcome.
1
2